diff --git a/servers/puppet/modules/zulip/files/limits.conf b/servers/puppet/modules/zulip/files/limits.conf new file mode 100644 index 0000000000..7104fdcdb4 --- /dev/null +++ b/servers/puppet/modules/zulip/files/limits.conf @@ -0,0 +1,58 @@ +# /etc/security/limits.conf +# +#Each line describes a limit for a user in the form: +# +# +# +#Where: +# can be: +# - an user name +# - a group name, with @group syntax +# - the wildcard *, for default entry +# - the wildcard %, can be also used with %group syntax, +# for maxlogin limit +# - NOTE: group and wildcard limits are not applied to root. +# To apply a limit to the root user, must be +# the literal username root. +# +# can have the two values: +# - "soft" for enforcing the soft limits +# - "hard" for enforcing hard limits +# +# can be one of the following: +# - core - limits the core file size (KB) +# - data - max data size (KB) +# - fsize - maximum filesize (KB) +# - memlock - max locked-in-memory address space (KB) +# - nofile - max number of open files +# - rss - max resident set size (KB) +# - stack - max stack size (KB) +# - cpu - max CPU time (MIN) +# - nproc - max number of processes +# - as - address space limit (KB) +# - maxlogins - max number of logins for this user +# - maxsyslogins - max number of logins on the system +# - priority - the priority to run user process with +# - locks - max number of file locks the user can hold +# - sigpending - max number of pending signals +# - msgqueue - max memory used by POSIX message queues (bytes) +# - nice - max nice priority allowed to raise to values: [-20, 19] +# - rtprio - max realtime priority +# - chroot - change root to directory (Debian-specific) +# +# +# + +#* soft core 0 +#root hard core 100000 +#* hard rss 10000 +#@student hard nproc 20 +#@faculty soft nproc 20 +#@faculty hard nproc 50 +#ftp hard nproc 0 +#ftp - chroot /ftp +#@student - maxlogins 4 +zulip soft nofile 40000 +zulip hard nofile 50000 + +# End of file diff --git a/servers/puppet/modules/zulip/manifests/base.pp b/servers/puppet/modules/zulip/manifests/base.pp index a1421d055f..ab156b2eb3 100644 --- a/servers/puppet/modules/zulip/manifests/base.pp +++ b/servers/puppet/modules/zulip/manifests/base.pp @@ -68,6 +68,14 @@ class zulip::base { source => 'puppet:///modules/zulip/puppet.conf', } + file { '/etc/security/limits.conf': + ensure => file, + mode => 640, + owner => "root", + group => "root", + source => 'puppet:///modules/zulip/limits.conf', + } + file { '/etc/apt/apt.conf.d/02periodic': ensure => file, mode => 644,